NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5142 | vendor advisory |
https://lists.debian.org/debian-lts-announce/2022/01/msg00013.html | third party advisory mailing list |
https://security.gentoo.org/glsa/202310-02 | third party advisory vendor advisory |